
MSP Systems Engineer
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States.
• Analyze phishing incidents, suspicious login activities, and account compromises.
• Engage in threat hunting, log review, containment, and resolution efforts.
• Spearhead response initiatives for security incidents related to Microsoft 365 and Azure.
• Work collaboratively with security partners and vendors during active incidents.
• Conduct reviews after incidents and refine prevention strategies.
• Develop and enhance Conditional Access policies and identity security measures.
• Oversee and optimize security features within Microsoft Defender and Entra ID.
• Establish security baselines and hardening standards across client environments.
• Enhance workflows for MFA, privileged access, and identity governance.
• Provide support and troubleshooting for Azure infrastructure and Azure Virtual Desktop settings.
• Manage complex escalations that involve networking, virtualization, storage, and authentication.
• Lead migration projects involving Microsoft 365, Azure, servers, and cloud infrastructure.
• Assist in automation and infrastructure-as-code projects.
• Act as the Tier 3 escalation point for advanced technical challenges.
• Mentor junior engineers and contribute to the establishment of technical standards.
• Produce documentation, operational runbooks, and replicable processes.
• Identify recurring issues and create sustainable solutions.
• Over 5 years of progressive IT experience.
• Minimum of 2 years dedicated to security operations.
• Extensive experience with the Microsoft 365 security stack, including Defender for Office 365, Defender for Endpoint, Defender for Identity, Entra ID Protection, and Conditional Access at scale.
• Strong foundational knowledge of Azure, including Entra ID, Azure Virtual Desktop, VNets, NSGs, Private Endpoints, and RBAC.
• Familiarity with infrastructure-as-code practices using Bicep or Terraform.
• Comprehensive incident response experience with real-world BEC, ransomware incidents, or account takeovers.
• Proficient in PowerShell scripting for administrative automation, Microsoft 365/Azure modules, and script troubleshooting or modification.
• Exceptional written communication skills for incident reports, RCA documentation, and client-facing summaries.
• Certifications SC-200, SC-300, or AZ-500 are advantageous.
• Operational experience with Blackpoint Cyber MDR is a plus.
• Practical experience with HaloPSA, NinjaOne/NinjaRMM, CIPP, Hudu, and Barracuda Email Protection is a plus.
• Experience in designing CIS- or NIST CSF-aligned baselines for SMB clients using Microsoft 365 and Azure is beneficial.
• Candidates must be located on the East Coast or Central US.
• Must be available during a P1.
• Annual performance bonus linked to security KPIs (mean time to detect, mean time to contain, reduction of recurring incidents).
• Health insurance coverage.
• Simple IRA plan.
• Initial 12 days of PTO (accrual increases with length of service).
• 8 paid holidays.
• Stipend for home office expenses.
JRAD
Agility Technologies Inc
Astrolab
Get handpicked remote jobs straight to your inbox weekly.